Security researchers have discovered a new attack targeting macOS systems running on Apple Silicon. Dubbed “SysBumps,” this attack exploits speculative execution vulnerabilities in system calls to bypass kernel isolation and disrupt kernel address space layout randomization (KASLR), a critical security feature.
See also: New NotLockBit ransomware targets Windows and macOS

The research team from Korea University, led by Hyerean Jang, Taehun Kim, and Youngjoo Shin, presented their findings in a paper titled "SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple Silicon."
Their work represents the first successful KASLR break attack on macOS systems powered by Apple's custom ARM-based chips .
KASLR is a defense mechanism that randomizes the layout of kernel memory, making it more difficult for attackers to predict the location of specific functions or data structures. By violating KASLR, malicious actors can potentially exploit other vulnerabilities more easily, compromising the security of the system.
See also: New Meeten malware targets macOS and Windows users
The SysBumps attack exploits speculative execution, a performance optimization technique used in modern processors.

By exploiting Spectre -like vulnerabilities in certain macOS system calls, researchers demonstrated that an unprivileged attacker could cause transient memory accesses to kernel addresses, even with kernel isolation enabled.
A key element of the attack involves using the Translation Lookaside Buffer (TLB) as a side channel to extract information about the kernel's memory layout. The research team reshaped the TLB structure of several M-series processors, revealing previously unknown details about its architecture.
The SysBumps attack works by constructing a token oracle that can determine whether a given kernel address is valid or not. This allows attackers to gradually map the memory space and eventually determine its base address, effectively breaking KASLR.
See also: MacOS faces AI-Powered Malware attacks
A Kernel Break attack is an advanced method of exploiting vulnerabilities at the core level of an operating system. This type of attack involves targeting the kernel, which serves as a bridge between software applications and hardware. By compromising the kernel, attackers can gain privileged access to the system, bypassing standard security mechanisms. Kernel Break attacks often involve exploiting zero-day vulnerabilities or unsafe system calls, which makes them particularly difficult to detect and prevent. Implementing strong security measures, such as kernel-level integrity checks and timely system updates, are critical to defending against these sophisticated threats.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
